Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.0

    MEDIUM
    CVE-2006-4922

    Unrestricted file upload vulnerability in starnet/editors/htmlarea/popups/images.php in Site@School (S@S) 2.4.02 and earlier allows remote attackers to upload and execute arbitrary files with executable extensions.... Read more

    Affected Products : siteatschool
    • Published: Sep. 21, 2006
    • Modified: Apr. 03, 2025
  • 2.6

    LOW
    CVE-2006-4919

    Directory traversal vulnerability in starnet/editors/htmlarea/popups/images.php in Site@School (S@S) 2.4.02 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the dir parameter.... Read more

    Affected Products : siteatschool
    • Published: Sep. 21, 2006
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2006-4923

    Cross-site scripting (XSS) vulnerability in search.php in eSyndiCat Portal System allows remote attackers to inject arbitrary web script or HTML via the what parameter.... Read more

    Affected Products : esyndicat_portal_system
    • Published: Sep. 21, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-4904

    Dynamic variable evaluation vulnerability in cmpi.php in Qualiteam X-Cart 4.1.3 and earlier allows remote attackers to overwrite arbitrary program variables and execute arbitrary PHP code, as demonstrated by PHP remote file inclusion via the xcart_dir par... Read more

    Affected Products : x-cart
    • Published: Sep. 21, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-4905

    PHP remote file inclusion vulnerability in index.php in Artmedic Links 5.0 allows remote attackers to execute arbitrary PHP code via a URL in the id parameter, which is processed by the readfile function.... Read more

    Affected Products : artmedic_links
    • Published: Sep. 21, 2006
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2006-4908

    OSU 3.11alpha and 3.10a allows remote attackers to obtain sensitive information via a URL containing an * (asterisk) wildcard, which displays all matching file and directory information.... Read more

    Affected Products : osu_httpd
    • Published: Sep. 21, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-4912

    PHP remote file inclusion vulnerability in PHP DocWriter 0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the script parameter.... Read more

    Affected Products : php_docwriter
    • Published: Sep. 21, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-4906

    SQL injection vulnerability in modules/calendar/week.php in More.groupware 0.74 allows remote attackers to execute arbitrary SQL commands via the new_calendarid parameter.... Read more

    Affected Products : more.groupware
    • Published: Sep. 21, 2006
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2006-4907

    OSU 3.11alpha and 3.10a allows remote attackers to obtain sensitive information via a URL to a non-existent file, which displays the web root path in the resulting error message.... Read more

    Affected Products : osu_httpd
    • Published: Sep. 21, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-4913

    Directory traversal vulnerability in chat/getStartOptions.php in AlstraSoft E-friends 4.85 allows remote attackers to include arbitrary local files and possibly execute arbitrary code via a .. (dot dot) sequence and trailing null (%00) byte in the lang pa... Read more

    Affected Products : e-friends
    • Published: Sep. 21, 2006
    • Modified: Apr. 03, 2025
  • 2.6

    LOW
    CVE-2006-4914

    Directory traversal vulnerability in A.l-Pifou 1.8p2 allows remote attackers to read arbitrary files via ".." sequences in the ze_langue_02 cookie, as demonstrated by using the choix_lng parameter to choix_langue.php to indirectly set the cookie, then acc... Read more

    Affected Products : a.l-pifou
    • Published: Sep. 21, 2006
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2006-4910

    The web administration interface (mainApp) to Cisco IDS before 4.1(5c), and IPS 5.0 before 5.0(6p1) and 5.1 before 5.1(2) allows remote attackers to cause a denial of service (unresponsive device) via a crafted SSLv2 Client Hello packet.... Read more

    • Published: Sep. 21, 2006
    • Modified: Apr. 03, 2025
  • 2.6

    LOW
    CVE-2006-4909

    Cross-site scripting (XSS) vulnerability in Cisco Guard DDoS Mitigation Appliance before 5.1(6), when anti-spoofing is enabled, allows remote attackers to inject arbitrary web script or HTML via certain character sequences in a URL that are not properly h... Read more

    Affected Products : guard_ddos_mitigation_appliance
    • Published: Sep. 21, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-4911

    Unspecified vulnerability in Cisco IPS 5.0 before 5.0(6p2) and 5.1 before 5.1(2), when running in inline or promiscuous mode, allows remote attackers to bypass traffic inspection via a "crafted sequence of fragmented IP packets".... Read more

    • Published: Sep. 21, 2006
    • Modified: Apr. 03, 2025
  • 6.4

    MEDIUM
    CVE-2006-4438

    Heap-based buffer overflow in SpIDer for Dr.Web Scanner for Linux 4.33, and possibly earlier versions, allows remote attackers to execute arbitrary code via an LHA archive with an extended header that contains a long directory name.... Read more

    Affected Products : dr.web
    • Published: Sep. 20, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-4890

    Multiple PHP remote file inclusion vulnerabilities in UNAK-CMS 1.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the dirroot parameter to (1) fckeditor/editor/filemanager/browser/default/connectors/php/connector.php or (2) ... Read more

    Affected Products : unak_cms
    • Published: Sep. 19, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-4892

    SQL injection vulnerability in faqview.asp in Techno Dreams FAQ Manager Package 1.0 allows remote attackers to execute arbitrary SQL commands via the key parameter.... Read more

    Affected Products : faq_manager_package
    • Published: Sep. 19, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-4895

    IDevSpot NexieAffiliate 1.9 and earlier allows remote attackers to delete arbitrary affiliates via a modified id parameter to delete.php.... Read more

    Affected Products : nixieaffiliate
    • Published: Sep. 19, 2006
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2006-4894

    Cross-site scripting (XSS) vulnerability in forms/lostpassword.php in iDevSpot NixieAffiliate 1.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the error parameter.... Read more

    Affected Products : nixieaffiliate
    • Published: Sep. 19, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-4891

    SQL injection vulnerability in ArticlesTableview.asp in Techno Dreams Articles & Papers Package 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the key parameter.... Read more

    Affected Products : articles_and_papers_package
    • Published: Sep. 19, 2006
    • Modified: Apr. 03, 2025
Showing 20 of 294848 Results